Keep a pristine copy of the flash image, and a way back to it

assets/flash.img was gitignored, so the only copy of the never-booted image lived
on one disk. The emulator writes to that image, so a session can leave edited
settings or a damaged EEPROM behind with nothing to restore from.

assets/pristine/ now holds the image as first generated, gzipped and checksummed,
and is tracked deliberately. Gzip takes it from 2 MiB to 2.3 KiB because the image
is nearly all 0xFF, which is what makes keeping it in git reasonable. The live
image and its .bak-* files stay ignored.

Two checksums are recorded, for the archive and for its contents, so a corrupted
archive is distinguishable from one that was replaced.

tools/restore_flash.sh verifies, diffs, or restores. Restore backs up the current
image first, then re-checks the result, since a restore that silently half-worked
would be worse than none.

Verified by deliberately corrupting the live image: --diff reported 32 differing
bytes, restore backed up and rewrote it, and --diff then reported no change. The
image is currently byte-identical to what make_flash.py produces, so this is the
genuine original rather than a copy of something already used.
This commit is contained in:
mckero committed 2026-08-28 12:20:13 +01:00
1 parent 19997e85e1
commit 1364d46e97
5 files changed
+102 -1

No files matched your search

+5
View File
@@ -1,5 +1,10 @@
# Generated flash image: 2 MB, rebuilt from calibration.bin by tools/make_flash.py.
# The live image is a build artifact and the emulator writes to it.
assets/flash.img
assets/flash.img.bak-*
# ...but assets/pristine/ is tracked on purpose: it is the never-booted
# reference to fall back to when a session leaves the image in a bad state.
!assets/pristine/
# Host build output for the CW timing harness.
build/